Prelude is now Origin: the endpoint AI observability company
The endpoint matters again
For the first time in more than a decade, the endpoint is becoming the center of a major architectural shift.
Endpoint security has historically developed in response to changes in how work gets done. The rise of email and files produced Antivirus. The rise of cloud applications and increasingly powerful software produced Endpoint Detection and Response.
Now, work is changing again.
AI agents are moving from chat windows into browsers, terminals, desktop applications, and operating systems. They are writing code, manipulating files, accessing company data, calling tools, and taking actions on behalf of employees. There is a reason products such as Codex, Claude Code, and Cowork run locally: the endpoint is where the context, permissions, applications, and data required to do meaningful work come together.
The rise of agentic work will create the next generation of endpoint security. But we believe (and as we saw last week with the new SACR report on endpoint) that the next generation of endpoint security will look much more like observability, because understanding how agents act on the endpoint is becoming the new primary security risk to organizations.
The primary risk is no longer limited to an external adversary executing recognizably malicious software. Organizations are inviting a rapidly growing population of autonomous actors into their environments, giving them legitimate permissions, and asking them to be as productive as possible.
The critical question is therefore changing from:
"Is this software malicious?"
to:
"What is this agent actually doing?"
Organizations will need to understand what agents see, what they are asked to do, which tools they use, what data they access, and what actions they take. They will need to distinguish productive work from dangerous behavior, even when both are performed through legitimate applications and authorized accounts.
That is the problem Origin exists to solve.
We believe this is one of the rare moments in a career when a new category can be built on top of a global architectural shift. That is why we have decided to go all in on Origin and capitalize on the need for endpoint AI observability.
How we got here
We founded Prelude Security to help organizations answer a specific question: Are we protected?
The products we built were offensive in nature, spanning adversary emulation, security-control validation, and continuous control monitoring. They were all based on the same thesis: by safely testing critical infrastructure, organizations could identify weaknesses before adversaries exploited them. That thesis remains valid. AI has helped create a new generation of well-funded companies focused on automated penetration testing, red teaming, and exposure management.
But our work also revealed something else.
When we conducted offensive tests, endpoint-focused techniques were often surprisingly successful. Many actions went undetected, not because of a single missing signature or misconfigured control, but because of structural limitations in the way endpoint defenses were designed.
That led us to three realizations.
First, our DNA was endpoint-first. We had developed deep expertise in operating-system internals, endpoint defenses (our team also wrote the definitive book on the topic), and how security controls actually behave under attack.
Second, the limitations we observed were broader than individual product gaps. Existing endpoint tools were designed primarily to identify known forms of malicious behavior, not to make arbitrary machine-driven work understandable.
Third, the next generation of endpoint technology would require a fundamentally different architecture.
We assembled a small research team to work backward from first principles and ask what a modern endpoint platform should look like. We emerged with several core beliefs:
- The future of endpoint technology will increasingly be built in user mode rather than depending on invasive kernel architectures.
- Signatures and known-malicious patterns will become less effective as AI produces novel, contextual, and highly variable behavior.
- The next generation of endpoint security will be built around trace-driven observability.
That research became Origin.
Origin then moved rapidly from a research project into a commercial platform, with meaningful enterprise contracts and large production endpoint deployments. It became increasingly clear that building Prelude and Origin simultaneously would prevent us from giving either one the focus it deserved.
We therefore made the decision to focus the entire company on Origin.
What this means
We will continue supporting Prelude customers for the full duration of their current contracts. We also hope to bring many of those customers with us as we build the Origin platform.
Origin is a new name and a new focus, but it is built on the same technical DNA, backed by the same investors, and led by the same commitment to solving consequential security problems.
Over the past year, we have shared pieces of this transition, including the $16 million financing we raised to accelerate the development of Origin. Today, we are making the transition official.
Thank you to the customers, investors, partners, employees, alumni, and friends who continue to support us, particularly through this evolution.
We are grateful to have the opportunity to focus completely on building the definitive endpoint platform for the age of AI.
Welcome to Origin.